Skip to content

Assessment

External Vulnerability Scan

A scoped assessment of internet-facing hosts and services, ranked by severity with clear remediation notes for your IT team.

Security analyst reviewing external network scan results on dual monitors in a quiet office

Who it is for

Small and midsize firms that need a clear picture of weaknesses visible from the public internet before attackers find them.

What you receive

A written findings report with severity rankings, evidence samples, and practical remediation steps your staff or MSP can act on.

Included

  • Discovery of in-scope public IP ranges and hostnames
  • Authenticated or unauthenticated scanning as agreed in the scope letter
  • Severity ranking aligned to common vulnerability scoring practices
  • Executive summary suitable for leadership and a technical appendix for IT
  • One clarification call after report delivery

Outside this engagement

  • Intrusion testing that attempts to exploit findings for access
  • Remediation work on your systems
  • Continuous monitoring subscriptions
  • Social engineering or phishing exercises

How we work

  1. Scope call to confirm assets, blackout windows, and contacts
  2. Written scope letter and scan schedule
  3. External scanning within the agreed window
  4. Manual review of high-severity findings to reduce noise
  5. Report delivery and follow-up clarification call

Preparation

Provide an accurate list of public IPs and domains, plus a technical contact reachable during the scan window.

Constraints

Scanning is limited to systems you own or are authorised to test. Out-of-scope hosts are excluded.